
CVE-2026-22010-Android-Intent-Redirection-to-Exported-Component
Proof-of-concept for CVE-2026-22010 Android intent redirection: demonstrates an exported activity forwarding intents to attacker-controlled internal…

Proof-of-concept for CVE-2026-22010 Android intent redirection: demonstrates an exported activity forwarding intents to attacker-controlled internal…

A flexible playground for Android CTF challenges.

idb is a tool to simplify some common tasks for iOS pentesting and research

Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.

Robust Frida-based tool to dump decrypted iOS apps as .ipa from a jailbroken device supports App Store, sideloaded and system.

An updated Frida iOS dump tool supporting the latest Frida 17.5.2 APIs

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

iOS customization app powered by CVE-2022-46689. No jailbreak required.

CVE-2017-2370

iOS Application w/Implementation of CVE-2024-27804

Dylib injection for iOS 11.0 - 11.1.2 with LiberiOS and Electra jailbreaks

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Static analysis tool for iOS applications that extracts links, API keys, subdomains, binary info, linked libraries, and strings to aid mobile…

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Extracts decrypted IPA files from jailbroken iOS devices using Frida for reverse engineering, security analysis, and mobile app pentesting.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…